Only more efficient in that nobody's throwing lots of chunky GPUs at it.
But as far as bitcon presents it, proof of work is needed to resolve the problem of keeping a honest transaction log in an untrusted environment.
So that whole block (which is maybe what you're calling the "output"), does contain the puzzle solution as well as all the latest transactions. But the actual specifics of the puzzle (which is currently brute-force SHA1 reversing), aren't super important. It could always be swapped out for some other task.
You seem to be saying that The Miners have to verify transactions to claim their reward? When you say "which are all verified separately" - you mean verified by the same miner who publishes the block? If so then the bitcoin network as a whole benefits from their energy use.
On the other hand, I see your point that the make-work is not intrinsically linked to transaction verification. But my understanding is, its the difficulty of the make-work that protects the block-chain from being hijacked by ..er... 'the bad guys', whomever they may be.
So, the whole thing kinda makes sense, and the 'make-work' is like an energy commitment that keeps the whole thing integrated. The assumption being, the total commitment of all bitcoin users will always be greater than the commitment of any single attacker/attacker group.
"By convention, the first transaction in a block is a special transaction that starts a new coin owned by the creator of the block. This adds an incentive for nodes to support the network, and provides a way to initially distribute coins into circulation, since there is no central authority to issue them."